Skip to content
RESEARCH INDEX BREACHROAD / INTELLIGENCE NOTE

AlphaGo’s Move 37: When AI Played What Humans Could Not Understand

In 2016, AlphaGo played a move that experts thought was a mistake — but it turned out to be brilliant. Why this moment in the party explains the opportunities and risks of AI in cybersecurity.

PUBLIC RESEARCH
AUTHOR
/ Penetration Tester (OSCP, PNPT)
PUBLISHED
9 July 2026
READING TIME
13 min read
TOPIC
History
AlphaGo’s Move 37: When AI Played What Humans Could Not Understand

Not every breakthrough moment in our industry is an attack. Some are moments when the world realized that something fundamental was changing. On March 10, 2016, in the second game of the historic match between the AlphaGo program and one of the best Go players in history, Lee Sedol, the computer made move number 37. The commentators were speechless. The move was so unusual that many experts initially considered it a mistake - something no serious player would play. And then, several dozen moves later, it turned out that it was a brilliant move that determined the victory. This is the moment when artificial intelligence showed that it can not only be fast, but also creative in a way that humans don’t understand. And that’s why it’s worth knowing when thinking about AI in cybersecurity.

Why go and not chess

In 1997, the Deep Blue computer defeated the world chess champion - and although it was loud, it was “explainable”: chess, despite its complexity, succumbs to the brute force of computation that calculates millions of variants. Go was considered an impregnable fortress for decades. Reason? Scale. The number of possible positions in go exceeds the number of atoms in the universe. It cannot be “calculated”. A good game of Go requires something that sounds almost human - intuition, a sense of shape, an assessment of position that cannot be reduced to simple calculation.

So when DeepMind announced that its program had defeated a professional player and then faced a legend like Lee Sedol, the AI ​​world held its breath. AlphaGo didn’t count everything by force - it learned the game from millions of games and from competitions with itself, building a kind of “intuition” expressed in neural networks.

A move that looked like a mistake

And then move 37 was made. AlphaGo placed the stone in a place that violated the recognized rules of the game - on the so-called the fifth line, in a situation where human theory had suggested otherwise for centuries. The commentators, all outstanding players, were convinced that it was a program error. Lee Sedol himself was so surprised that he got up from the table and left for a few minutes to cool down and think about his position.

It was later calculated that the probability of a human making this move was approximately one in ten thousand. It was not a “human, but better” movement. It was a foreign movement - growing out of a completely different way of looking at the game. And yet, as the party progressed, his genius became more and more obvious. Move 37 built influence on the board that ultimately determined AlphaGo’s victory in this game. The machine didn’t copy human knowledge - it went beyond it.

The human answer: “divine movement”

It is worth adding that this was not a unilateral capitulation of man. In the fourth game, Lee Sedol played his own genius move - move 78, later called “the divine touch” - so unexpected that it was AlphaGo that got lost and lost the game. Ultimately, the match ended with a score of 4:1 for the machine, but this one win for Lee Sedol showed something important: humans and AI can surprise each other, and the most interesting thing is the meeting of two different types of intelligence, not the simple superiority of one over the other.

What does this have to do with cybersecurity

It would seem that the game of go is a distant curiosity. In fact, Movement 37 is one of the best metaphors we have for understanding what AI means for our industry — in good and bad ways.

On the side of opportunity: AI can find solutions that humans would not think of. In defense, this means the ability to detect attack patterns hidden in a sea of ​​data, catching anomalies that are not described by any rule - as we write in AI on the defense side. AI can “see” relationships invisible to the analyst.

On the risk side: this same creativity in the hands of an attacker is disturbing. If AI can find “move 37” in Go, it can also find a non-obvious attack path, an unusual chain of vulnerabilities, a way to bypass security measures that the defender did not anticipate. This is the real dimension of offensive AI - not only faster, but also thinking differently.

And on the deepest lesson side: move 37 is a symbol of AI opacity. No one - including the creators of AlphaGo - could explain “why” it was good when they made the move. The machine “knew” but couldn’t explain it in human terms. This is the crux of the problem we face today with every AI implementation: how can we trust a system whose decisions we cannot fully explain? In cybersecurity, where the stakes are a false alarm or a missed attack, “because the AI ​​said so” cannot be the end of the conversation. Therefore, when implementing we leave the human in the loop.

The moment that set the course

The 37 movement was a signal in 2016 that the era in which AI merely replicates human knowledge is coming to an end — and the era in which AI is transcending it is beginning. For many researchers, this was the moment when abstract thoughts about “intelligent machines” became tangible. What happened next with language models and generative AI was a continuation of the same trajectory that Move 37 was a public, dramatic harbinger of.

For our industry, this is the founding moment of the dual nature of AI: a powerful ally of the defender and a dangerous tool in the hands of the attacker - and, above all, a technology whose power goes hand in hand with opacity.

Summary

Move 37 is the moment when the machine made a move so alien to human intuition that experts thought it was a mistake - but it turned out to be brilliant. AlphaGo did not copy human knowledge of Go; has gone beyond it, showing that AI can be creative in ways we don’t understand. For cybersecurity, this is the best metaphor we have: the same ability that allows AI to spot a hidden attack in a sea of ​​data, in the hands of an attacker means opaque intrusion paths, and its opacity forces us to keep humans in the loop. The Go party of 2016 still teaches us the most important thing about artificial intelligence: its power and its mystique are two sides of the same coin.

Are you implementing AI and want to benefit from its capabilities without blindly trusting opaque decisions? Let’s talk - secure AI implementation support is one of our specialities.

Frequently asked questions (FAQ)

What was move 37 in the AlphaGo game with Lee Sedol? This was AlphaGo’s 37th move in the second game of the 2016 match - a stone placed in a place so unusual that experts considered it a mistake, but which turned out to be brilliant and helped the machine win the game. It was estimated that a human would play this move with a probability of about 1 in 10,000. It has become a symbol of AI creativity that goes beyond human intuition.

Why was winning Go a bigger breakthrough than winning chess? Because it is too complex for “brute force” computation - the number of possible positions exceeds the number of atoms in the universe, so they cannot be counted. Playing well requires something like intuition. Defeating Master Go meant that the AI ​​had mastered a task considered to be the domain of human intuition, not just quick calculation.

What does Movement 37 say about AI in cybersecurity? That AI can find solutions that are not obvious to humans - which in defense means detecting hidden attack patterns, and in the hands of an attacker, non-obvious intrusion paths. It also highlights a key problem: opacity. AlphaGo “knew” the traffic was good, but couldn’t explain it - so AI decisions cannot be trusted uncritically and human oversight is needed.

Has anyone ever won a game with AlphaGo? Yes. Lee Sedol won the fourth game thanks to his own brilliant, unexpected move (move 78, dubbed the “divine touch”), which confused AlphaGo. The match ended with a score of 4:1 for the machine, but this one win showed that humans and AI can surprise each other.

SHARE / COPY